Page: [1] [2] [3] |
The Pope
Decisive Send PM
Posts: 5183
Threads: 123 Mood: Refreshed Money: £201.52 (D) (+ Friend)
|
ok. maybe a small donation of 0.0.25?
________________
Learn to look, look to learn. |
17.08.03 11:38 Post #31 | [Hide Sig (14)] [Profile] [Quote] |
meiapaul
Statusless Send PM Posts:
Threads: Money: £0.00 (D) (+ Friend)
|
donated. spend it wisely
|
17.08.03 11:48 Post #32 | [Hide Sig (0)] [Profile] [Quote] |
The Pope
Decisive Send PM
Posts: 5183
Threads: 123 Mood: Refreshed Money: £201.52 (D) (+ Friend)
| ________________
Learn to look, look to learn. |
17.08.03 11:50 Post #33 | [Hide Sig (14)] [Profile] [Quote] |
jay
Statusless Send PM Posts:
Threads: Money: £0.00 (D) (+ Friend)
|
how do you know if ye got that blaster virus hingy?
|
17.08.03 20:19 Post #34 | [Hide Sig (0)] [Profile] [Quote] |
routine_error
Statusless Send PM Posts: 1081
Threads: 25 Money: £6.36 (D) (+ Friend)
|
" How can I tell if the worm is affecting my computer?
Some customers whose computers have been infected may not notice the presence of the worm at all, while others who are not infected may experience problems because the worm is attempting to attack their computer. Typical symptoms may include Windows XP and Windows Server 2003 systems rebooting every few minutes without user input, or Windows NT 4.0 and Windows 2000 systems becoming unresponsive. Whether you are experiencing these symptoms or not, Microsoft recommends that you take the following action immediately:
If you're running Windows Server 2003 or Windows NT 4.0, follow Steps 1–3 for home users on this page.
If you're running Windows XP or Windows 2000, follow all Steps 1–4 for home users on this page."
- http://www.microsoft.com/security/incident/blast_faq.asp
|
17.08.03 20:43 Post #35 | [Hide Sig (1)] [Profile] [Quote] |
The Pope
Decisive Send PM
Posts: 5183
Threads: 123 Mood: Refreshed Money: £201.52 (D) (+ Friend)
|
In terms for you to understand. The virus makes your computer restart every few minutes. This might not always happen if you have it though. Best to get latest AV updates and scan for it.
________________
Learn to look, look to learn. |
18.08.03 07:06 Post #36 | [Hide Sig (14)] [Profile] [Quote] |
jay
Statusless Send PM Posts:
Threads: Money: £0.00 (D) (+ Friend)
|
i got the update scanned with the remover tool from symantec and..........
"the blaster virus was not found ount ure computer"
hurrah
|
18.08.03 13:12 Post #37 | [Hide Sig (0)] [Profile] [Quote] |
routine_error
Statusless Send PM Posts: 1081
Threads: 25 Money: £6.36 (D) (+ Friend)
|
this is confusing... that Remote Procedure Call (RPC) thing was remotely transmitted over the net to a vulnerable (open) port on one's computer, overflowing the RPC buffer, causing it to shut your computer down with a custom made packet. If this is the same as this 'Blaster Virus', then it is not a virus at all. I would have said so earlier, but found it odd that Microsoft would call it a virus as well. I suppose for the 60 seconds that your computer is staring you in the face like a showdown and who's going to turn her off first, it could be like a virus. However nothing that I'm aware would stay on the computer, causing it to crash again, the attacker would simply send another custom (duplicate, i'd imagine) packet through your open system, crashing it once again. I'm fairly sure this is the case, as once I put up a firewall (here and at my mother's place of business) the crashing came to a hault. I then instald patches and turned off the firewalls, everything was fine. If the patch was only to stop the exploit (that's what it is, an exploit, not a virus), then it would have no capabilities of removing a virus from your system, however, I have had no problems since with the affected computers. I still find it odd, though, that everyone seems to like to call it a virus. Well, maybe everyone is wrong.
|
18.08.03 18:42 Post #38 | [Hide Sig (1)] [Profile] [Quote] |
Zogger!
Looking For Status Send PM Posts: 3954
Threads: 62 Money: £93.82 (D) (+ Friend)
|
I thought it was also set up to perform DDOS attacks on the microsoft website... who knows. There is also an Anti Virus Virus now.
________________
You know I'm a dancing machine |
18.08.03 18:48 Post #39 | [Hide Sig (8)] [Profile] [Quote] |
routine_error
Statusless Send PM Posts: 1081
Threads: 25 Money: £6.36 (D) (+ Friend)
|
oh, I see. that should work, actually. odd.
|
18.08.03 18:50 Post #40 | [Hide Sig (1)] [Profile] [Quote] |
C1
Looking For Status Send PM Posts: 0
Threads: 0 Money: £0.18 (D) (+ Friend)
|
ya here cause i read the news paper on my tv ill tell u all. Mind u i might get messed up cause i read about a lot of stuff. Anyways ya zogger is right it was supposed to attack microsoft but they used the redirectory link to get all the infected folks that were still infected at 1:01 saturday or some date like that. to all go to microsoft and crash it. But microsoft got smart and disconnected the redirectory link and ppl were still able to come to microsoft to download the update to stop this virus. Also another virus was like a good sumaritain and it makes u download the patch from microsoft. But errors still happen from it. Also some obig virus(i forgot the name) made a list of about 10000 emails and use those to send the viruses to others. And im on that list cause i got an email sayint the virus could not be sent to Billy Joe. and this was the virus update from C1. I would know more but my news paper updates everyday so i forgot some stuff.
Edit: and also the msblaster also said as a joke stupid bill gates why not make ur programs better and all this wouldnt happen
|
20.08.03 23:44 Post #41 | [Hide Sig (2)] [Profile] [Quote] |
routine_error
Statusless Send PM Posts: 1081
Threads: 25 Money: £6.36 (D) (+ Friend)
|
Edit: and also the msblaster also said as a joke stupid bill gates why not make ur programs better and all this wouldnt happen
lol
well, i heard 'SOBIG' on TechTV, they said a bunch of crap about it, but it's all the same old shit, 'go to symantic for more information, we don't know a damn thing!'... or the same shit that you've already heard before someplace else.
|
21.08.03 00:57 Post #42 | [Hide Sig (1)] [Profile] [Quote] |
The Pope
Decisive Send PM
Posts: 5183
Threads: 123 Mood: Refreshed Money: £201.52 (D) (+ Friend)
|
I-Worm.Sobig.f, W32/Sobig.F-mm, W32/Sobig.f@MM, WORM_SOBIG.F W32/Sobig-F is a worm that spreads via email and network shares.
W32/Sobig-F copies itself to the Windows folder as winppr32.exe and sets one of the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\TrayX
= \winppr32.exe /sinc
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\TrayX
=
The worm sends itself, using its own SMTP engine, as an attachment to email addresses collected from various files on the victim's computer. When it distributes itself via email it forges the sender's email address, making it difficult to know who is truly infected.
The email has the following format:
Subject line: Chosen from -
Re: That movie
Re: Wicked screensaver
Re: Your application
Re: Approved
Re: Re: My details
Re: Details
Your details
Thank you!
Message text: Chosen from -
Please see the attached file for details.
See the attached file for details
Attached file: Chosen from -
movie0045.pif
wicked_scr.scr
application.pif
document_9446.pif
details.pif
your_details.pif
thank_you.pif
document_all.pif
your_document.pif
W32/Sobig-F also attempts to spread by copying itself to Windows network shares and uses the Network Time Protocol to one of several servers in order to determine the current date and time. If the date is September 10 2003 or later the worm stops working
________________
Learn to look, look to learn. |
21.08.03 07:02 Post #43 | [Hide Sig (14)] [Profile] [Quote] |
C1
Looking For Status Send PM Posts: 0
Threads: 0 Money: £0.18 (D) (+ Friend)
|
hmm my tv said it also took like 500 email addys and use those to send it. Or maybe i have a virus that doesnt do one damn thing on my computer.
|
21.08.03 18:13 Post #44 | [Hide Sig (2)] [Profile] [Quote] |
Page: [1] [2] [3] |
Your Comments: